{"id":"CVE-2026-97438","title":"In the Linux kernel, the following vulnerability has been resolved:\n\nfs/ntfs3: validate index entry key bounds\n\n[BUG]\nA malformed NTFS directory index entry can advertise a key_size larger\nthan the bytes actually present in its NTFS_DE p…","summary":"In the Linux kernel, the following vulnerability has been resolved:\n\nfs/ntfs3: validate index entry key bounds\n\n[BUG]\nA malformed NTFS directory index entry can advertise a key_size larger\nthan the bytes actually present in its NTFS_DE p…","severity":"high","cvss":7.1,"cvssVector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:H","vendor":"Linux","product":"Linux","affected":["Linux >= 1da177e4c3f41524e886b7f1b8a0c1fc7321cac2 < a8f4fb6a7d58974ffc9aed597401528b181d76dc","Linux >= 1da177e4c3f41524e886b7f1b8a0c1fc7321cac2 < 0257e3ea00e19129f3ad5c039d8b8fdff0796835","Linux >= 1da177e4c3f41524e886b7f1b8a0c1fc7321cac2 < 98d6e5d9dc1d34dcffc61549617581a5fe1ef807","Linux < 6.12.111","Linux < 6.18.53","Linux (all versions)"],"published":"2026-09-24","updated":"2026-09-25","sourceUpdated":"2026-09-25T13:17:27.430","source":"NVD","sourceUrl":"https://nvd.nist.gov/vuln/detail/CVE-2026-97438","references":[{"url":"https://git.kernel.org/stable/c/0257e3ea00e19129f3ad5c039d8b8fdff0796835","label":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/98d6e5d9dc1d34dcffc61549617581a5fe1ef807","label":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/a8f4fb6a7d58974ffc9aed597401528b181d76dc","label":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"}],"tags":["nvd","cve.org"],"ingestedAt":"2026-09-24T16:47:15.879Z","slug":"CVE-2026-97438","body":"## Overview\n\nIn the Linux kernel, the following vulnerability has been resolved:\n\nfs/ntfs3: validate index entry key bounds\n\n[BUG]\nA malformed NTFS directory index entry can advertise a key_size larger\nthan the bytes actually present in its NTFS_DE payload. Directory lookup\nthen passes that malformed key to cmp_fnames(), which can read past the\nend of the kmalloc'ed index buffer.\n\nBUG: KASAN: slab-out-of-bounds in fname_full_size fs/ntfs3/ntfs.h:590 [inline]\nBUG: KASAN: slab-out-of-bounds in cmp_fnames+0x1ea/0x230 fs/ntfs3/index.c:46\nRead of size 1 at addr ffff88801c313018 by task syz.6.3365/9279\n\nCall Trace:\n __dump_stack lib/dump_stack.c:94 [inline]\n dump_stack_lvl+0xbe/0x130 lib/dump_stack.c:120\n print_address_description mm/kasan/report.c:378 [inline]\n print_report+0xd1/0x650 mm/kasan/report.c:482\n kasan_report+0xfb/0x140 mm/kasan/report.c:595\n __asan_report_load1_noabort+0x14/0x30 mm/kasan/report_generic.c:378\n fname_full_size fs/ntfs3/ntfs.h:590 [inline]\n cmp_fnames+0x1ea/0x230 fs/ntfs3/index.c:46\n hdr_find_e.isra.0+0x3ed/0x670 fs/ntfs3/index.c:762\n indx_find+0x4b5/0x900 fs/ntfs3/index.c:1186\n dir_search_u+0x2c0/0x460 fs/ntfs3/dir.c:254\n ntfs_lookup+0x1cc/0x2a0 fs/ntfs3/namei.c:85\n __lookup_slow+0x241/0x450 fs/namei.c:1816\n lookup_slow fs/namei.c:1833 [inline]\n walk_component+0x31c/0x570 fs/namei.c:2151\n link_path_walk+0x592/0xd60 fs/namei.c:2519\n path_lookupat+0x138/0x660 fs/namei.c:2675\n filename_lookup+0x1f3/0x560 fs/namei.c:2705\n filename_setxattr+0xad/0x1c0 fs/xattr.c:660\n path_setxattrat+0x1d8/0x280 fs/xattr.c:713\n __do_sys_lsetxattr fs/xattr.c:754 [inline]\n __se_sys_lsetxattr fs/xattr.c:750 [inline]\n __x64_sys_lsetxattr+0xd0/0x150 fs/xattr.c:750\n ...\n\nAllocated by task 9279:\n kasan_save_stack+0x39/0x70 mm/kasan/common.c:56\n kasan_save_track+0x14/0x40 mm/kasan/common.c:77\n kasan_save_alloc_info+0x37/0x60 mm/kasan/generic.c:573\n poison_kmalloc_redzone mm/kasan/common.c:400 [inline]\n __kasan_kmalloc+0xc3/0xd0 mm/kasan/common.c:417\n kasan_kmalloc include/linux/kasan.h:262 [inline]\n __do_kmalloc_node mm/slub.c:5650 [inline]\n __kmalloc_noprof+0x2bd/0x900 mm/slub.c:5662\n kmalloc_noprof include/linux/slab.h:961 [inline]\n indx_read+0x41d/0xad0 fs/ntfs3/index.c:1059\n indx_find+0x447/0x900 fs/ntfs3/index.c:1179\n dir_search_u+0x2c0/0x460 fs/ntfs3/dir.c:254\n ntfs_lookup+0x1cc/0x2a0 fs/ntfs3/namei.c:85\n __lookup_slow+0x241/0x450 fs/namei.c:1816\n lookup_slow fs/namei.c:1833 [inline]\n walk_component+0x31c/0x570 fs/namei.c:2151\n link_path_walk+0x592/0xd60 fs/namei.c:2519\n path_lookupat+0x138/0x660 fs/namei.c:2675\n filename_lookup+0x1f3/0x560 fs/namei.c:2705\n filename_setxattr+0xad/0x1c0 fs/xattr.c:660\n path_setxattrat+0x1d8/0x280 fs/xattr.c:713\n __do_sys_lsetxattr fs/xattr.c:754 [inline]\n __se_sys_lsetxattr fs/xattr.c:750 [inline]\n __x64_sys_lsetxattr+0xd0/0x150 fs/xattr.c:750\n ...\n\n[CAUSE]\nThe index-header validators only validated INDEX_HDR-level geometry.\nThey did not walk each NTFS_DE to verify entry alignment, subnode\nlayout, or that key_size fit inside the entry payload. They also\nallowed a last sentinel entry to carry a non-zero key_size.\n\n[FIX]\nWalk every NTFS_DE in ntfs3's index-header validators and reject\nentries with invalid layout, mismatched subnode state, oversized\nkey_size, or non-zero sentinel keys before lookup or log replay can\nconsume them.\n\n## Remediation\n\nRefer to the linked advisories for vendor-supplied fixes and affected version ranges.","depth":"twilight","depthScore":39,"depthScoreParts":{"impact":39.1,"likelihood":0,"exploitation":0,"ransomware":0},"changes":[{"seq":210591,"id":"CVE-2026-97438","ts":1790316055916,"field":"cvss","old":null,"new":"7.1"},{"seq":210590,"id":"CVE-2026-97438","ts":1790316055916,"field":"severity","old":"none","new":"high"}]}